A large-scale fraud campaign is targeting users in Uzbekistan, Belarus, and Tajikistan through hundreds of fake government and news websites designed to collect personal information and lure victims into fraudulent financial schemes.
Cybersecurity researchers at F6 identified more than 360 fraudulent domains connected to the campaign. The sites imitate government programs, public assistance initiatives, and regional news organizations while promoting fake offers involving cash payments, financial assistance, or passive-income opportunities.
The operation relies heavily on trust.
Victims are presented with websites that closely resemble legitimate government portals or local news pages. The visual design, wording, and presentation are intended to make the offers appear official enough that users will provide contact information without immediately recognizing the fraud.
Some of the websites operate as basic landing pages. They advertise supposed government benefits or investment opportunities and ask visitors to provide information such as their name and telephone number.
Other sites use a more elaborate approach by impersonating regional news organizations and publishing fabricated stories about government financial programs before directing visitors to questionnaires or registration forms.
The objective is not always to steal money during the first interaction.
In many cases, the initial website functions as a lead-generation system for the attackers. Once a victim enters a phone number or other contact information, scammers can move the fraud away from the website and continue the operation through telephone calls, email, or other online communication.
Users in Uzbekistan have been shown fraudulent offers promising weekly payments of 15 million Uzbek soums, or approximately $1,300.
The amount is large enough to attract attention while the initial registration process remains deliberately simple. Victims may initially be asked for little more than a name and telephone number.
After obtaining those details, scammers can contact victims while posing as personal account managers connected to the supposed program.
The next stage can involve requests for a supposed commission or other payment that the victim is told must be made before receiving the promised funds.
The financial offer is only one possible path used by the campaign.
Victims may also be pressured to provide additional personal information, identification documents, banking information, or access to their electronic devices.
Some are reportedly instructed to install a mobile application that scammers claim is necessary to register for the program or verify their identity.
The application can instead contain malicious software capable of giving attackers access to the device.
Once installed, malicious software can give attackers access to the victim’s device and potentially expose sensitive information or financial accounts.
That creates a second layer of risk beyond the original scam.
A victim who initially believes he or she is applying for a financial benefit can end up providing attackers with direct access to a phone or other device containing banking and identity information.
The campaign also seeks identity documents.
Some victims may be instructed to submit scans or photographs of passports as part of a supposed verification process.
Stolen passport information can be reused in additional fraud, including fraudulent loan applications and further phishing attacks.
This makes the campaign more than a simple advance-fee scam.
The infrastructure combines government impersonation, media impersonation, data harvesting, social engineering, malware delivery, and potential identity theft into a single fraud chain.
The fake websites serve as the entry point.
The actual damage can occur later through human interaction after attackers have obtained enough information to establish contact and build credibility.
The use of fake news websites adds another layer of deception because victims may believe they are reading an independent report confirming the existence of a government program.
A fabricated article can give a fraudulent offer the appearance of outside validation, making the scam more convincing than a standalone advertisement.
Government impersonation works in a similar way.
People are more likely to trust a website that appears to represent a ministry, public agency, social program, or financial initiative than an unfamiliar commercial page.
Attackers exploit that trust by reproducing recognizable design elements, official-sounding language, registration forms, and promises tied to economic assistance.
F6 researchers said the scammers carefully reproduce the visual appearance and language used by legitimate government portals and news organizations.
That level of imitation can make visual inspection alone an unreliable method of determining whether a website is legitimate.
The campaign also demonstrates how modern fraud operations can separate the initial lure from the final theft.
A fake website may collect only a telephone number.
The attacker can then use that information to move the victim into a more controlled environment where a scammer can apply pressure, answer questions, request payments, or persuade the victim to install software.
That process gives attackers time to build credibility and adapt the scheme to the individual victim.
It also makes disruption more difficult because shutting down one fraudulent domain does not necessarily terminate the operation. Attackers can register additional domains, rebuild similar websites, redirect traffic, and continue contacting people whose information has already been collected.
More than 360 domains associated with the campaign have been identified, indicating that the operation relies on a broad web infrastructure rather than a single fraudulent site.
The true number of victims remains unknown.
Researchers have not publicly identified the individuals or organization responsible for operating the campaign, and no confirmed victim count has been released.
The campaign reinforces several basic indicators users should watch for when confronted with unexpected government payment or investment offers.
Government benefits should be verified through independently located official agency websites rather than links contained in advertisements, unsolicited messages, or unfamiliar news articles.
Requests to pay money before receiving a government benefit should be treated with particular caution.
Users should also be extremely wary when an alleged government program instructs them to install unfamiliar mobile applications, provide remote access to a device, submit passport scans through an unverified website, or disclose banking credentials.
The most dangerous element of this campaign is not the appearance of any single fraudulent page.
It is the combination of impersonation, contact harvesting, direct social engineering, malicious software, and identity theft that can begin with something as simple as entering a telephone number into a convincing-looking website.
🔥 NOW AVAILABLE! 🔥
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 1 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed
🔥 Kindle Edition 👉 https://a.co/d/9EoGKzh
🔥 Paperback 👉 https://a.co/d/9EoGKzh
🔥 Hardcover Edition 👉 https://a.co/d/0ITmDIB
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 2 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed just like the first one.
🔥 Kindle Edition 👉 https://a.co/d/1xlx7J2
🔥 Paperback 👉 https://a.co/d/a7vFHN6
🔥 Hardcover Edition 👉 https://a.co/d/efhu1ON
Get your copy today and experience poetry like never before. #InkAndFire #PoetryUnleashed #FuelTheFire
🚨 NOW AVAILABLE! 🚨
📖 THE INEVITABLE: THE DAWN OF A NEW ERA 📖
A powerful, eye-opening read that challenges the status quo and explores the future unfolding before us. Dive into a journey of truth, change, and the forces shaping our world.
🔥 Kindle Edition 👉 https://a.co/d/0FzX6MH
🔥 Paperback 👉 https://a.co/d/2IsxLof
🔥 Hardcover Edition 👉 https://a.co/d/bz01raP
Get your copy today and be part of the new era. #TheInevitable #TruthUnveiled #NewEra
🚀 NOW AVAILABLE! 🚀
📖 THE FORGOTTEN OUTPOST 📖
The Cold War Moon Base They Swore Never Existed
What if the moon landing was just the cover story?
Dive into the boldest investigation The Realist Juggernaut has ever published—featuring declassified files, ghost missions, whistleblower testimony, and black-budget secrets buried in lunar dust.
🔥 Kindle Edition 👉 https://a.co/d/2Mu03Iu
🛸 Paperback Coming Soon
Discover the base they never wanted you to find. TheForgottenOutpost #RealistJuggernaut #MoonBaseTruth #ColdWarSecrets #Declassified



